<?php


switch($act)
{
	case 'contact':
		Show('address');
		$tpl = 'contact';
		break;	
	
	case 'send':
		SendMail();
		$tpl = 'finish';
		break;
		
	case 'sendLink':
		SendLinkToFriend();
		$tpl = 'finish';
		break;
			
	default:		
		Show('address');
		$tpl = 'list';
		break;
}
function Show($str)
{
	global $db, $info,$title_bar, $cat, $lg, $title_page;

	if(isset($_GET['cat1'])){

		global $cat1;

		$id = $cat1['id'];

		$title_bar = $cat1["name_$lg"];

		$cat = $cat1;

		if($lg == "vn"){

			$title_page = strtolower($cat1["title_". $_SESSION['lg']]); 

		}

		$sql = "select content_vn, content_en from infos where name_vn like '%".$str. " ". $_SESSION['lg']."%'";    

		$info = $db->getRow($sql);
	}else{

		$sql = "select content_vn, content_en from infos where name_vn like '%".$str. " ". $_SESSION['lg']."%'";    

		$info = $db->getRow($sql);

		$sql = 'select content_vn, content_en from categories where id='.CleanSQLInjection(trim(isset($_GET['cid'])?$_GET['cid']:''));

		$cat = $db->getRow($sql);

		$r = $cat;

		$title_bar = $r['name_'.$_SESSION['lg']];
	}
}
function ShowContact()
{
	global $db, $contact, $email;
	$sql = 'select content_vn, content_en from info where name_vn=\'contact\'';    
    $contact = $db->getRow($sql);
	$sql = 'select content_vn, content_en from info where name_vn=\'email\'';    
    $email = $db->getRow($sql);
}
function SendMail()
{
	global $FullUrl;
	
	include("./includes/mail_config.php");
	$fh = fopen("EmailTemplate/Contact.html", 'r');
	$template = fread($fh, filesize("EmailTemplate/Contact.html"));
	fclose($fh);
	$page = $FullUrl . '/thank-you.html';
	
	$key=substr($_SESSION['key'],0,4);
	$number = $_REQUEST['number_captcha'];
	//echo $number.'|'.$key;
	if($number==$key && $number != ''){
		//echo 'right';
	
	
		global $db, $mail;
		$sql = "select content_vn, content_en from infos where name_vn like '%contact mail%'";
		$r = $db->getRow($sql);
		$mail_to = strip_tags($r['content_vn']);
		$mail_subject = 'Contact from '. $_POST['name_contact'] . ' - ' . $_POST['company_contact'];
		
		$template = str_replace('[NAME_SEND]',$_POST['name_contact'], $template);
		$template = str_replace('[COMPANY_SEND]',$_POST['company_contact'] , $template);
		$template = str_replace('[PHONE_SEND]',$_POST['phone_contact'], $template);
		$template = str_replace('[EMAIL_SEND]',$_POST['email_contact'], $template);
		$template = str_replace('[ADDRESS_SEND]',$_POST['address_contact'], $template);
		$template = str_replace('[LINK1_SEND]',$_POST['link1_contact'], $template);
		$template = str_replace('[LINK2_SEND]',$_POST['link2_contact'], $template);
		$template = str_replace('[COMMENT_SEND]',$_POST['comment_contact'], $template);
		
		if(isset($_FILES['fileatt']['name'] ) && $_FILES['fileatt']['size']>0){
			$img = $_FILES['fileatt']['name'];
			$start = strpos($img,".");
			$type = substr($img,$start,strlen($img));
			if(CorrectFileTypes($type))
			{
				$filename = 'fileatt-'.time().$type;
				$filename = strtolower($filename);
				copy($_FILES['fileatt']['tmp_name'], "./kam/upload/att/" . $filename) ;
				$mail->AddAttachment("./kam/upload/att/" . $filename);	 
			}
			else
			{
				page_transfer2($FullUrl . '/');
				$_SESSION['mess'] = WRONG_FILE_TYPE_MESS;
			}
		}
		
		$mail->Subject = $mail_subject;
		$mail->MsgHTML($template);
		$mail->AddAddress($mail_to, "Webmaster");
		
		if(!$mail->Send()) {
			$_SESSION['mess'] = SEND_EMAIL_UNSUCCESSFULLY_MESS;
			$page = $FullUrl . '/index.html';
		} else {
			$_SESSION['mess'] = SEND_EMAIL_SUCCESSFULLY_MESS;
		}
	}
	else{
		//echo 'wrong';
	} 
	$_SESSION['key'] = '';
	unset($_SESSION['key']);
	page_transfer2($page);
}

?>